MR60 Firmware
39 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for MR60 Firmware, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
MR60 Firmware CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 3 |
| 2026-07 | 0 |
| 2026-08 | 3 |
| 2026-09 | 0 |
Severity
How the 39 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical14
- High11
- Medium13
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting MR60 Firmware.
- CVE-2026-11738Insufficient input validation in certain NETGEAR Nighthawk routers allows administrators to tamper with the device.4.4
- CVE-2026-11739Command injection vulnerability in some NETGEAR Nighthawk devices6.4
- CVE-2026-11814Command injection vulnerability in certain NETGEAR Nighthawk and Orbi routers6.8
- CVE-2026-0418Certain NETGEAR devices allow administrators to tamper with system4.5
- CVE-2026-0417Insufficient input validation in certain NETGEAR routers4.5
- CVE-2026-9210Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router4.5
- CVE-2021-34983NETGEAR Multiple Routers httpd Missing Authentication for Critical Function Information Disclosure Vulnerability6.5
- CVE-2021-34982NETGEAR Multiple Routers httpd Stack-based Buffer Overflow Remote Code Execution Vulnerability8.8
- CVE-2023-36187Buffer Overflow vulnerability in NETGEAR R6400v2 before version 1.0.4.118, allows remote unauthenticated attackers to execute arbitrary code via crafted URL to httpd.9.8
- CVE-2022-27642This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this ...8.8
- CVE-2022-27647This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit...8.0
- CVE-2022-48322NETGEAR Nighthawk WiFi Mesh systems and routers are affected by a stack-based buffer overflow vulnerability. This affects MR60 before 1.1.7.132, MS60 before 1.1.7.132, R6900P before 1.3.3.154, R700...9.8
- CVE-2022-48176Netgear routers R7000P before v1.3.3.154, R6900P before v1.3.3.154, R7960P before v1.4.4.94, and R8000P before v1.4.4.94 were discovered to contain a pre-authentication stack overflow.7.8
- CVE-2021-45539Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84, R7960P before 1.4.2.84, R8000 before 1.0.4.74, R8000P before 1.4.2.84, MR60 ...8.4
- CVE-2021-45540Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126, R7900 before 1.0.4.46, R7900P before 1.4.2.84, R7960P before 1.4.2.84, R800...8.4
Product grouping is registry-driven, with AI assist and human review. How it works